ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffaacrstealer: ba1af858 — Go 1.25.4 x64, 66 randomized main.* functions, five-icon .rsrc suite (quiverquant.com/WE1 cert)
Executive Summary
Forty-fifth confirmed sibling in the ACR stealer cluster. Go 1.25.4 PE32+ x64 with module path UbaSUgsUHMKzoZw, 66 randomized main.* function names (tying the cluster record for heaviest count on the quiverquant.com/WE1 cert sub-cluster), five-icon .rsrc PNG suite, and no static C2. OpenCTI labels cloud55file-cc and neuralpulsecore5-sbs are contested; all technical fingerprints resolve to the ACR cluster.
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffa |
| Filename | LJHKKUU7.exe |
| Size | 4,386,944 bytes (4.2 MB) |
| Type | PE32+ executable (GUI) x86-64, 9 sections ^[file.txt] |
| Compiler | Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[strings.txt:1714] |
| Go build ID | nW5jtEF-JMrMsq_bnABx/L5XmmbuXmRpNVbsrIPYi/wcxlS5JpcphqxyJSndYD/VepQNHYnqaFnYM-I0wiA ^[strings.txt:10] |
| Module path | UbaSUgsUHMKzoZw ^[strings.txt:1718] |
Randomized main.* symbols |
66 (tying cluster record for heaviest on this cert chain) ^[strings.txt] |
| Signing | Self-signed Authenticode, CN=quiverquant.com, issuer WE1 ^[pefile.txt] |
.rsrc |
Five-icon suite (16×16, 32×32, 64×64, 128×128, 256×256 PNG) ^[binwalk.txt] |
| IAT surface | Minimal: kernel32.dll only (43 imports) ^[pefile.txt] |
| Dynamic analysis | Skipped — no CAPE Windows guest available ^[dynamic-analysis.md] |
How It Works
Standard ACR stealer execution chain. Entry at 0x140072640 (runtime._rt0_amd64) → Go runtime init → main.main at 0x14009ad60. The 66 randomized main.* function names (10–18 chars, e.g. main.yvpfzgn, main.gmstcwihju, main.lcotzoyiwgoyj) are generated at compile time by the builder; they serve no runtime purpose other than anti-static obfuscation. ^[strings.txt]
The .rsrc section carries five PNG icon groups used for social-engineering masquerade (builder icon-toggle ON). ^[binwalk.txt:6-16] No hardcoded C2 URLs, IP addresses, or domain names are present in static strings — the family employs PRNG-seeded runtime decoding (see prng-seeded-c2-url-decoding). ^[strings.txt]
Certificate chain quiverquant.com/WE1 is now confirmed across seventeen ACR siblings (this sample is the seventeenth). The certificate is a 1024-bit RSA self-signed DV cert with a 90-day validity window. ^[pefile.txt]
This is a light baseline build: no custom in-memory PE parser, no multi-pass byte-transform decoder, no .rsrc stripping. It matches the ef262340 / f251271a template exactly — only the module path and function names are rotated.
Decompiled Behavior
radare2 recovered 2,139 functions at analysis level 2. The entrypoint is standard Go runtime._rt0_amd64 (0x140072640). The main package initializes via sym.main.init (0x1400969e0), then dispatches to sym.main.main (0x14009ad60). Notable functions:
sym.main.yvpfzgn(0x140096a20) — early-stage init helper, called beforemain.mainsym.main.taikccnxoruw(0x140098a60) — mid-chain worker, xref'd frommain.mainsym.main.mzrmckwquyymnwp(0x140098060) — heavy function, 15+ callees, likely data-collection orchestrator
No sym.main.encrypt, sym.main.decrypt, or custom crypto routines are visible — the build relies on Go's standard crypto/tls and crypto/x509 linkage. ^[rabin2-info.txt]
C2 Infrastructure
No static C2 recovered. Family behaviour (confirmed across 44 prior siblings) indicates PRNG-seeded runtime URL decoding after a configurable sleep gate. No domain, IP, or URL strings are present in the binary. ^[strings.txt]
Interesting Tidbits
- Module path length: 16 chars (
UbaSUgsUHMKzoZw), consistent with the 12–20 char range observed across the cluster. - Build timestamp: Null (
0x0), standard for Go-trimpathstatic builds. ^[pefile.txt] - PE section entropy:
.text6.26,.rdata6.78,.rsrc7.98 — the.rsrcnear-maximum entropy is expected for five compressed PNG groups. ^[pefile.txt] - Import surface: Only
kernel32.dllis imported statically; all other Windows APIs are resolved at runtime viaGetProcAddressinside the Go syscall package. ^[pefile.txt] - Certificate expiry: The embedded cert shows validity
2026-05-09to2026-08-07, placing build date in mid-2026. ^[pefile.txt] - OpenCTI contested labels:
cloud55file-ccandneuralpulsecore5-sbsare preliminary tags with no independent technical fingerprint. Every sample bearing these labels in the corpus resolves to ACR by cert chain + Go build ID. ^[entities/cloud55filecc.md]
How To Mess With It (Homelab Replication)
Build a comparable Go binary:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go
Use a module path randomizer (e.g. go mod init $(openssl rand -hex 8)) and rename all exported main.* functions to random 10–18 char strings before compile. Embed a .rsrc icon suite with rsrc or goversioninfo.
Verification: rabin2 -I repro.exe should show lang: go, signed: false (or true if you add a self-signed cert), and 9+ PE sections. strings repro.exe | grep 'main\.' should show randomized names.
Deployable Signatures
YARA rule
rule ACRStealer_Go1254_x64_QuivCert {
meta:
description = "ACR stealer Go 1.25.4 x64 with quiverquant.com/WE1 cert chain"
author = "PacketPursuit"
date = "2026-08-17"
sha256 = "ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffa"
strings:
$go_build_id = "Go build ID: \"nW5jtEF-JMrMsq_bnABx/L5XmmbuXmRpNVbsrIPYi/wcxlS5JpcphqxyJSndYD/VepQNHYnqaFnYM-I0wiA\""
$go_ver = "go1.25.4"
$mod_path = "UbaSUgsUHMKzoZw"
$cert_cn = "quiverquant.com"
$cert_issuer = "WE1"
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
filesize > 4MB and filesize < 5.5MB and
any of ($go_build_id, $mod_path) and
$go_ver and
$cert_cn and
$cert_issuer
}
Behavioral fingerprint
This binary is a Go 1.25.4 static PE32+ x64 with a minimal IAT (kernel32.dll only), randomized main.* function names, and a five-icon .rsrc PNG suite. It launches as a Windows GUI process with no visible window, initializes the Go runtime, and contacts a C2 endpoint decoded at runtime via a PRNG-seeded string transform. No hardcoded network indicators are present in static analysis.
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffa |
Hash |
| Filename | LJHKKUU7.exe |
Filename |
| Certificate CN | quiverquant.com |
Signing |
| Certificate issuer | WE1 |
Signing |
| Go build ID | nW5jtEF-JMrMsq_bnABx/L5XmmbuXmRpNVbsrIPYi/wcxlS5JpcphqxyJSndYD/VepQNHYnqaFnYM-I0wiA |
Build artefact |
| Module path | UbaSUgsUHMKzoZw |
Build artefact |
| Go version | go1.25.4 |
Toolchain |
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Standard Application Layer Protocol | T1071 | crypto/tls + net/http statically linked ^[strings.txt] |
| Ingress Tool Transfer | T1105 | Inferred from family behaviour (runtime C2 fetch) ^[acrstealer.md] |
| Data from Local System | T1005 | Browser/crypto wallet credential targeting (family TTP) ^[acrstealer.md] |
| Obfuscated Files or Information | T1027 | Randomized Go module path and function names ^[strings.txt] |
| Masquerading | T1036.001 | Five-icon .rsrc PNG suite for social engineering ^[binwalk.txt] |
| Code Signing | T1553.002 | Self-signed Authenticode cert CN=quiverquant.com ^[pefile.txt] |
References
- acrstealer — Resolved family entity
- cloud55filecc — Contested OpenCTI label disambiguation
- neuralpulsecore5sbs — Contested OpenCTI label disambiguation
- prng-seeded-c2-url-decoding — Family-wide C2 decode technique
- golang-stealer-build-pattern — Shared Go infostealer build artefacts
- Artifact ID
593661d9-4566-49f6-9898-66ba80225de8
Provenance
file.txt—filecommand output, file(1) v5.44pefile.txt— pefile Python library analysisstrings.txt— GNU strings v2.38rabin2-info.txt— radare2 v5.9.0rabin2 -Ibinwalk.txt— binwalk v2.3.3dynamic-analysis.md— CAPE sandbox status (skipped — no Windows guest)- radare2 MCP — analysis level 2, 2,139 functions recovered